Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard

A global enterprise is experiencing a significant increase in sophisticated phishing attacks targeting its employees and supply chain partners. These attacks often involve highly personalized content and rapidly evolving tactics. The cybersecurity architect needs to implement a security operations strategy that proactively detects these advanced threats, enriches alerts with contextual information, and enables security analysts to perform rapid investigations and coordinated responses. Which technical strategy is MOST effective for addressing this challenge?

  1. AUtilizing a Security Orchestration, Automation, and Response (SOAR) platform for automated playbooks.
  2. BDeploying an advanced Endpoint Detection and Response (EDR) solution across all workstations.
  3. CEstablishing a Security Information and Event Management (SIEM) system with custom correlation rules.
  4. DImplementing a comprehensive Threat Intelligence Platform (TIP) integrated with security controls.
Show answer & explanation

Correct answer: D. Implementing a comprehensive Threat Intelligence Platform (TIP) integrated with security controls.

A Threat Intelligence Platform (TIP) is specifically designed to aggregate, process, and disseminate threat intelligence, enriching alerts with contextual information about attacker tactics and evolving phishing threats, which is crucial for proactive detection and rapid investigation of sophisticated attacks.

Why the other options are wrong

  • A. SOAR automates responses and orchestrates security tools, but it relies on an underlying detection and intelligence source. Without robust threat intelligence (like from a TIP), SOAR's effectiveness against evolving threats is limited.
  • B. EDR focuses on endpoint activity, but while useful, it doesn't provide the broad, aggregated, and contextualized threat intelligence needed to proactively understand and combat rapidly evolving, sophisticated phishing campaigns across an enterprise and its supply chain.
  • C. SIEM collects logs and detects events, but it often lacks the deep, curated, and context-rich threat intelligence that a TIP provides, making it less effective at proactively identifying highly sophisticated and rapidly changing phishing campaigns.

Threat Intelligence Platform (TIP)

A TIP aggregates, processes, and disseminates actionable threat intelligence from various sources, enriching security alerts and enabling proactive threat detection and response.

  • Collects and normalizes threat data.
  • Provides context on attacker TTPs.
  • Integrates with security controls for proactive defense.
  • Enhances incident investigation capabilities.

Memory trick: TIP is the 'Cyber Detective' gathering 'Clues' on 'Phishing Attacks'.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions